the holder of the corresponding parental responsibilities.
78 Nevertheless, that age
limit cannot be set below 13 years. In the event that a Member State chooses not to
regulate this topic, the processing of data of children below the age of 16 years in that
context is only deemed lawful to the extent that consent is given or authorized by the
holder of the parental responsibility over the child.
The United States has a specific law for regulating the processing of personal data
of children under the age of 13 by operators of websites or online services.
79 The
Children’s Online Privacy Protection Act of 1998 (hereinafter COPPA) imposes
certain specific requirements for the processing of data on operators of websites or
online services directed to children under 13 years of age and on operators of other
websites or online services that have actual knowledge that they are collecting
personal information online from a child under 13 years of age. COPPA has assigned
the enforcement of its provisions to the FTC, at the federal level, and has given this
agency the power to promulgate rules to guide the interpretation and enforcement of
this Act. Taking into account that COPPA was enacted in 1998, and technology and
the risks that it poses to children have evolved radically since then, the FTC has
updated and expanded the focus of the COPPA regulations and has issued additional
guidance. Although the COPPA Act itself does not provide for specific penalties,
courts have determined damages pursuant to the Federal Trade Commission Act,
because COPPA infringements are considered to be unfair or deceptive trade
practices under that Act. Nevertheless, there is no private cause of action for
COPPA infringement, so states have to file civil actions to obtain injunctions and
damages in the interest of their citizens.
80
With regard to the consent of the minor when using the services regulated under
the COPPA, which consists in the single topic specifically regulated under the
GDPR regarding minors, COPPA determines, as a rule of thumb, that prior to any
collection, use, and or disclosure of personal information from a child under 13, the
respective operator must obtain verifiable parental consent. Furthermore, COPPA
regulates in detail the requirements for obtaining a verifiable parental consent,
defining admissible methods for this purpose.
Therefore, with respect to minors’ personal data protection, when using online
services and or websites, the United States of America has more detailed and
restrictive legislation than the European Union.
Other countries covered by this report do not have specific provisions on the
protection of minors’ personal data processed by electronic means.
81 In the absence
78 See the European Union Special Report, Sect. 2.2. Some European Union Member States have
already set their age limit under this GDPR provision. By way of example, after the full implementation of the GDPR, on the 25th of May 2018, France has set that age limit at 15 years through
its Law of 20 June 2018.
79 See the United States of America’s National Report, Sect. 2.3.
80 Important case law on this subject has been further developing processes for determining
damages. See the United States of America’s National Report, Sect. 2.3, referring to the case law
United States v. Boston Scientific Corp., 253 F. Supp. 2d 85, 98 (D. Mass. 2003).
81 See, for example, the Canadian National Report, Sect. 2.1.
Data Protection in the Internet: General Report
17
78 Nevertheless, that age
limit cannot be set below 13 years. In the event that a Member State chooses not to
regulate this topic, the processing of data of children below the age of 16 years in that
context is only deemed lawful to the extent that consent is given or authorized by the
holder of the parental responsibility over the child.
The United States has a specific law for regulating the processing of personal data
of children under the age of 13 by operators of websites or online services.
79 The
Children’s Online Privacy Protection Act of 1998 (hereinafter COPPA) imposes
certain specific requirements for the processing of data on operators of websites or
online services directed to children under 13 years of age and on operators of other
websites or online services that have actual knowledge that they are collecting
personal information online from a child under 13 years of age. COPPA has assigned
the enforcement of its provisions to the FTC, at the federal level, and has given this
agency the power to promulgate rules to guide the interpretation and enforcement of
this Act. Taking into account that COPPA was enacted in 1998, and technology and
the risks that it poses to children have evolved radically since then, the FTC has
updated and expanded the focus of the COPPA regulations and has issued additional
guidance. Although the COPPA Act itself does not provide for specific penalties,
courts have determined damages pursuant to the Federal Trade Commission Act,
because COPPA infringements are considered to be unfair or deceptive trade
practices under that Act. Nevertheless, there is no private cause of action for
COPPA infringement, so states have to file civil actions to obtain injunctions and
damages in the interest of their citizens.
80
With regard to the consent of the minor when using the services regulated under
the COPPA, which consists in the single topic specifically regulated under the
GDPR regarding minors, COPPA determines, as a rule of thumb, that prior to any
collection, use, and or disclosure of personal information from a child under 13, the
respective operator must obtain verifiable parental consent. Furthermore, COPPA
regulates in detail the requirements for obtaining a verifiable parental consent,
defining admissible methods for this purpose.
Therefore, with respect to minors’ personal data protection, when using online
services and or websites, the United States of America has more detailed and
restrictive legislation than the European Union.
Other countries covered by this report do not have specific provisions on the
protection of minors’ personal data processed by electronic means.
81 In the absence
78 See the European Union Special Report, Sect. 2.2. Some European Union Member States have
already set their age limit under this GDPR provision. By way of example, after the full implementation of the GDPR, on the 25th of May 2018, France has set that age limit at 15 years through
its Law of 20 June 2018.
79 See the United States of America’s National Report, Sect. 2.3.
80 Important case law on this subject has been further developing processes for determining
damages. See the United States of America’s National Report, Sect. 2.3, referring to the case law
United States v. Boston Scientific Corp., 253 F. Supp. 2d 85, 98 (D. Mass. 2003).
81 See, for example, the Canadian National Report, Sect. 2.1.
Data Protection in the Internet: General Report
17
